CVE-2012-4792

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
91.83

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Internet Explorer for Windows XP (KB2799329)Windows
Security Update for Internet Explorer for Windows Server 2003 (KB2799329)Windows
Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 7 for Windows XP (KB2799329)Windows
Security Update for Internet Explorer 7 in Windows Vista (KB2799329)Windows
Security Update for Internet Explorer 7 in Windows Server 2008 (KB2799329)Windows
Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 8 for Windows XP (KB2799329)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows Vista (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows 7 (KB2799329) x86 based systemsWindows
Security Update for Internet Explorer 8 in Windows 7 (KB2799329) x86 based systems for SP1Windows
Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2799329) for SP1Windows
Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2799329)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2799329) for SP1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13035Security Update for Internet Explorer for Windows XP (KB2799329)
PATCH-13036Security Update for Internet Explorer for Windows Server 2003 (KB2799329)
PATCH-13038Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2799329)
PATCH-13039Security Update for Internet Explorer 7 for Windows XP (KB2799329)
PATCH-13041Security Update for Internet Explorer 7 in Windows Vista (KB2799329)
PATCH-13042Security Update for Internet Explorer 7 in Windows Server 2008 (KB2799329)
PATCH-13043Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2799329)
PATCH-13044Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2799329)
PATCH-13045Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2799329)
PATCH-13046Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2799329)
PATCH-13047Security Update for Internet Explorer 8 for Windows XP (KB2799329)
PATCH-13048Security Update for Internet Explorer 8 for Windows Server 2003 (KB2799329)
PATCH-13049Security Update for Internet Explorer 8 in Windows Vista (KB2799329)
PATCH-13050Security Update for Internet Explorer 8 in Windows Server 2008 (KB2799329)
PATCH-13051Security Update for Internet Explorer 8 in Windows 7 (KB2799329)
PATCH-13052Security Update for Internet Explorer 8 in Windows 7 (KB2799329)
PATCH-13053Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2799329)
PATCH-13054Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2799329)
PATCH-13055Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2799329)
PATCH-13056Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2799329)
PATCH-13057Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2799329)
PATCH-13058Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2799329)
PATCH-13059Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2799329)
PATCH-13060Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2799329)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234